Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-6859

Publication date:
13/01/2020
Multiple Insecure Direct Object Reference vulnerabilities in includes/core/class-files.php in the Ultimate Member plugin through 2.1.2 for WordPress allow remote attackers to change other users' profiles and cover photos via a modified user_id parameter. This is related to ajax_image_upload and ajax_resize_image.
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2020

CVE-2019-18893

Publication date:
13/01/2020
XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example access cookies and browsing history, spy on the user while they are surfing the web, and alter their surfing experience in almost arbitrary ways.
Severity CVSS v4.0: Pending analysis
Last modification:
22/01/2020

CVE-2019-18894

Publication date:
13/01/2020
In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to support Bank Mode functionality. A flaw in the processing of a command allows execution of arbitrary OS commands with the privileges of the currently logged in user. This allows for example attackers who compromised a browser extension to escape from the browser sandbox.
Severity CVSS v4.0: Pending analysis
Last modification:
21/01/2020

CVE-2019-19547

Publication date:
13/01/2020
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2011-2670

Publication date:
13/01/2020
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2013-6225

Publication date:
13/01/2020
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
17/01/2020

CVE-2014-9382

Publication date:
13/01/2020
Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation
Severity CVSS v4.0: Pending analysis
Last modification:
23/01/2020

CVE-2014-6059

Publication date:
13/01/2020
WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability
Severity CVSS v4.0: Pending analysis
Last modification:
05/01/2024

CVE-2014-5381

Publication date:
13/01/2020
Grand MA 300 allows a brute-force attack on the PIN.
Severity CVSS v4.0: Pending analysis
Last modification:
15/01/2020

CVE-2014-6038

Publication date:
13/01/2020
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2023

CVE-2014-6039

Publication date:
13/01/2020
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
Severity CVSS v4.0: Pending analysis
Last modification:
26/03/2020

CVE-2014-5380

Publication date:
13/01/2020
Grand MA 300 allows retrieval of the access PIN from sniffed data.
Severity CVSS v4.0: Pending analysis
Last modification:
23/01/2020